CVE-2026-44114: OpenClaw < 2026.4.20 - Environment Variable Namespace Collision via Workspace dotenv
OpenClaw before 2026.4.20 fails to properly reserve the OPENCLAW runtime-control environment namespace in workspace dotenv files, allowing attackers to override critical runtime variables. Malicious workspaces can set variables like OPENCLAWGITDIR to manipulate trusted OpenClaw runtime behavior during source-update or installer flows.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.4.20
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44114?
CVE-2026-44114 is classified as a critical vulnerability due to the potential for attackers to override essential runtime variables.
How do I fix CVE-2026-44114?
To fix CVE-2026-44114, update OpenClaw to version 2026.4.20 or later, which addresses the environment variable namespace collision issue.
What systems are affected by CVE-2026-44114?
CVE-2026-44114 affects all versions of OpenClaw prior to 2026.4.20.
What can attackers do with CVE-2026-44114?
Attackers can exploit CVE-2026-44114 to override critical OpenClaw runtime environment variables, potentially compromising application integrity.
Is CVE-2026-44114 related to dotenv files?
Yes, CVE-2026-44114 involves a namespace collision in workspace dotenv files which can be exploited by attackers.